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MEMORANDUM FOR: Director of Security 


FROM: ns a 
Deputy Director of Security (PTOS) 


SUBJECT: Office of Security Policy Definition 
Concerning Security Violations and Their 
Reporting by CIA Domestic Industrial 
Contractor Facilities 


1. Action Requested: It is requested that you sign 
Attachment One and Attachment Two forwarded with this 
memorandum, and that you forward Attachment One to the 
Director of Logistics and Attachment Two to the Director, 
NRO, together with exemplars of the Security Violation 
Report Form. 


2. Background: The DCI, when commenting on the 
Security Review Task Force Report of the oeaeite Boyce/Lee 
Cases, expressed concern that not akl security violations 


were being reported to ee: as required in Section I, 


Paragraph 6a(3) of the Industrial Security Manual. 
Agency regulations cur ontain no definition of a 
security violation. Attachments One and Two contain a 
definition of what constitutes a reportable security violation. 
Also included is a reporting form which would be used by 
Agency contractors to report such violations to Headquarters 

in a noncompartmented format. 


3, Staff Position: This new definition of a reportable 
security Violation represents the coordinated position of 
this Office, of the Security Staffs of the Office of Develap- 
ment and Engineering, the Office of Communications, the Office 
of Logistics, and of the NRO, as well as of the Special 
Security Canter. The Security Violation Report Form was 
designed by the Office of Development and Engineering and 
meets with the approval of the other Offices concerned. The 
Office of Communications has requesteu a cOpy of the two 
attachments and the Security Violation Report Form. We 
propose to forward them as requested following your signatures 
of Attachments One and Two. 
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4. Recommendation: It is recommended that you sign 
and forward the attached memoranda to the Director of 
Logistics and to the Director, NRO, along with copies of 
the Security Violation Report Form for further dissemination 


to the Director of Logistics and the appropriate NRO Program 
Offices. 
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Attachnents 
OS 7 5216 


Distribution: 
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DD/PTOS w/att copy 
OS Registry w/att c 
SSC w/att copy 6 of 
ISB w/att copy 7 of 
ISB chrono w/att cop 
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MEMORANDUM FOR: firector, National Reconnaissance Hffice 


FROM: Robert WW. Ganmbins 
hirector of Security 


SUBJECT: Security Violations Occurring at vRo 
Program Office Contractor Facilities -- 
Jefinition of and Reporting Procedures 


VEFE RENCE: Agreement for Reorganization of the NRP 
dated 11 Aucust 1565 


1. uring security audits conducted at Agency- funded 
and NRO- funded contractors as a result of the Boyce/Lee 
Case, it has become apparent that some contractors have not 
peen oroperly intersreting Section I, Paragraph (3) of the 
Ms Sedotrial Security Manual. Instead of reporting 
ail Security violations as required, many contractors have 
adopted the policy of reporting only violations which have, 


ja their judgment, resulted in compromise or wiich they felt 
could potentially result in compromise. They have not 
uniformly reperted other matters such as open safes or 
unsecured classified material found by guards, preferring 
to regard them simply as security "discrenancies’ rather 
than as violations. 

oe0. Re Director of Central Intedligence has expressed 
concern regarding this situation and agrees that suck a 
lacs of complete reporting is unacceptable. The following 
policy will, therefore, apply with regard.to all contracte 
under the cognizance of the Central IntellLizence Agency: 


“SECURITY VIOLATION: Aay breach of security 


regulations, requiremonts, procedures or suides by an 
individual which subjects classified or sensitive 
material or information to conpromise to unauthorized 
persous, or which places it in jeopardy where a con- 
promise could result, constitutes a reportable security 
violation. Such a breach includes both acts of omission 
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such as failure to properly secure classified or 
sensitive material, anid acts of commission such 

as discussion of classified or sensitive information 
over nonsecure telephone circuits. The information 
and materials referred to in this definition comprise 
Collateral classified, SCI classified, and those 
materials and information which are sensitive because 
they involve intelligence sources and methods." 


3. Pursuant to paragraph 2C(5) of reference, it is 
requested that you disseminate this definition to Programs 


25X1A 


A, 3, ant C for their notification of the appropriate contractors. 


4. Along with the definition, please forward a copy of 
the attached Security Violation Report Form, It may be repro- 
duced locally by each contractor a3 necessary. Please tell 
your Program Offices to inforn thelr contractors that the 
Security Violation Report Ferms, when filled in, are te be 
classified a minimum of SECRET because they relate to SCI 
contracts. Full Program names should not be used in reporting 
SCI violations on this Security Violation Report Form because 
the individual security files in which they will be maintained 
will not in every case be in 3 compartmented area. If it does 
become necessary for the contractor to report SCI details of a 
violation, those facts should be separately stated in an attach- 
ment which is to ba maintained by the Program Office under SCI 
control. 


5. Please advise this Office when the actions in paragraphs 
1 


3 and 4 have been accomnlished. 


FOR THE DIRECTOR OF CENTRAL INTELLIGENCE: 


Attachment 


HPistribution: 


Copy 1 - O/NRO 
2 - 2S0/NEO 
3 - D/Sec 
4 - DD/PTOS 
5 - OS/Reg 
6 - SSC 
7 - C/ISB 
8 IS3B chrono 


158 ca (29 Dec 77) 
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